Skip to content
JSON Tidy

JWT decoder and verifier

Paste a JSON Web Token to see its header and claims, when it expires, and whether the signature is valid. You can also sign new tokens for testing. Tokens and keys are processed in your browser and aren’t uploaded.

Decode and verify a JWT

The decoded header and payload appear here as soon as you paste a token. Decoding happens in your browser; the token isn’t uploaded.

How to verify a JWT signature

The header and payload of a JWT are Base64URL-encoded, not encrypted, so the decoder can show them without a key. Checking the signature does need a key. For HS256, HS384, and HS512 tokens, enter the shared secret the issuer signed with. For RS, PS, ES, and EdDSA tokens, paste the issuer’s public key, certificate, or key set.

A valid signature means the token was issued by whoever holds that key and hasn’t been edited since. The decoder also shows whether the token has expired. If you’re checking tokens in your own API, it should reject expired tokens and tokens whose iss or aud don’t match your service, even when the signature is valid.

Finding the secret or public key

An HS secret is usually set in the issuing server’s configuration, for example in an environment variable like JWT_SECRET. Identity providers sign tokens with a private key and publish the matching public keys as a JSON Web Key Set (JWKS). Paste the whole JWKS into the public key box, or enter its URL and choose Load keys. If the token has a kid header, the decoder uses it to pick the matching key.

ProviderPublic keys (JWKS)
Auth0https://YOUR_DOMAIN/.well-known/jwks.json
Amazon Cognitohttps://cognito-idp.REGION.amazonaws.com/USER_POOL_ID/.well-known/jwks.json
Microsoft Entra IDhttps://login.microsoftonline.com/TENANT_ID/discovery/v2.0/keys
Google sign-inhttps://www.googleapis.com/oauth2/v3/certs
Firebase Authenticationhttps://www.googleapis.com/service_accounts/v1/jwk/securetoken@system.gserviceaccount.com

Replace the capitalized parts with your own domain, region, or IDs. For other OpenID Connect providers, the JWKS URL is listed as jwks_uri at /.well-known/openid-configuration on the issuer’s domain.

Privacy and share links

Decoding, verifying, and signing use your browser’s Web Crypto API, so tokens and keys stay on your device. The only network request the tool makes is when you ask it to load public keys from a URL. Page analytics don’t record tokens.

A token that hasn’t expired can be used by anyone who has a copy, so it’s best to paste expired or test tokens where you can, and to keep production signing keys off websites, including this one.

Share links store the token after the # in the URL, a part browsers don’t send to servers. The signature is left out unless you tick Include the signature, so whoever opens the link can read the claims but can’t use the token.

Read the guide to how JWTs work, including claims, signing algorithms, and common mistakes